AFAIK, this key only exists to let users connect to the local REST server over HTTPS (it stops Chrome from complaining about insecure connections).
We could generate these keys on the client side per user, but there's no real risk to leaving it as-is.